CVE-2026-106503: Backstage: Scaffolder action input authorization bypass
### Impact An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources. ### Patches Patched in `@backstage/plugin-scaffolder-backend` version `4.1.0` ### Workarounds - Restrict affected Scaffolder actions to trusted users and configure source-control integrations with least-privilege credentials.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/plugin-scaffolder-backend 3.3.1, @backstage/plugin-scaffolder-backend 3.4.1, @backstage/plugin-scaffolder-backend 4.0.3, @backstage/plugin-scaffolder-backend 4.1.0.
Technical details
- Vendor
- Not specified
- Product
- @backstage/plugin-scaffolder-backend
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source